Fortinet Community

The community is a place to collaborate, share insights and experiences, and get answers to questions.

douglas1942's Topics

Hello, I have a BGP link on my Fortigate.  We recently had a case whereby the L3 link was still up even though the Internet was unavailable. Therefore,I want to set up an SLA (pinging to 8.8.8.8) t... See more...
Hello, I have a BGP link on my Fortigate.  We recently had a case whereby the L3 link was still up even though the Internet was unavailable. Therefore,I want to set up an SLA (pinging to 8.8.8.8) to monitor that the Internet is up. If not, then I need to remove all BGP routes or shut down that link. Is this going to be possible, or will the SLA only work with static routes ?   Thank you,
Hello, just trying to understand the benefit of Graceful Restart when you already have BGP Holdtime. For example with BGP Holdtime (default 180 seconds) a BGP peer will not drop the connection until... See more...
Hello, just trying to understand the benefit of Graceful Restart when you already have BGP Holdtime. For example with BGP Holdtime (default 180 seconds) a BGP peer will not drop the connection until 180 seconds without an update from the other side. Then we have Graceful restart which enables a peer to advise the other peer that it will be down for 120 seconds (default) while it upgrades or fails over. I want to understand what the point of 'graceful restart' is, if the Holdtime will not drop the connection for a longer period anyway ?
Hello, I have a Fortigate policy whereby I want to specify that a user has to belong to TWO user groups in order to pass the policy. However, I am finding that the user only needs to match one group... See more...
Hello, I have a Fortigate policy whereby I want to specify that a user has to belong to TWO user groups in order to pass the policy. However, I am finding that the user only needs to match one group, but I want BOTH groups to be matched.   Is there any way to do this ? Thank you.
Hello, I have an incoming route-map applying a MED metric of 10 to a received default route. I can see this metric of 10 showing in the route table so confirms it works.   However, I am also recei... See more...
Hello, I have an incoming route-map applying a MED metric of 10 to a received default route. I can see this metric of 10 showing in the route table so confirms it works.   However, I am also receiving another default route from another BGP peer with a MED metric of 1. I can see this route coming in, however it is not replacing the existing default route with metric 10.   I thought lowest metric wins. How come the new, lower metric default route is not taking over from the existing one ?   Thanks for any help.
Hello, I have a VDOM_A with an interface to our ISP that receives DHCP and a default route. I also have a BGP peer relationship in VDOM_A with VDOM_B. I want to automatically advertise the default ... See more...
Hello, I have a VDOM_A with an interface to our ISP that receives DHCP and a default route. I also have a BGP peer relationship in VDOM_A with VDOM_B. I want to automatically advertise the default route received from the ISP in VDOM_A to VDOM_B. Will this happen automatically or do I need to specify it in the BGP advertised network list or via the default-information-originate' command ?   Thank you.
Hello I want to configure a L2 VLXAN over IPSEC tunnel. Previously I have had this working with multiple VLANs that entered the Fortigate via tagged sub-interfaces (TRUNK interfaces from my switches... See more...
Hello I want to configure a L2 VLXAN over IPSEC tunnel. Previously I have had this working with multiple VLANs that entered the Fortigate via tagged sub-interfaces (TRUNK interfaces from my switches). However, this time, I have a single VLAN environment on both sides (ACCESS switchports connecting to untagged interfaces on my Fortigates), but that single VLAN is tagged differently on both sides e.g. SIDE_A=VLAN 10 & SIDE_B=VLAN 20. Therefore I need traffic entering SIDE_A Fortigate as VLAN 10 to exit SIDE_B Fortigate as VLAN 20. Is this possible at all ?
Hello, I am wanting a layer 2 trunk (supporting 5 VLANs) across a dialup IPSEC tunnel. I will have two Fortigate 60Es on each end for the L3 IPSEC tunnel, then will use VXLAN for the layer 2 trunkin... See more...
Hello, I am wanting a layer 2 trunk (supporting 5 VLANs) across a dialup IPSEC tunnel. I will have two Fortigate 60Es on each end for the L3 IPSEC tunnel, then will use VXLAN for the layer 2 trunking. In theory this should be possible with FortiOS, correct ?   Thank you.
Hello, I want to identify all BGP learned routes on a Fortigate and then apply a BGP Community attribute to them. I am using an inbound route-map on the BGP peer for this purpose, however it does se... See more...
Hello, I want to identify all BGP learned routes on a Fortigate and then apply a BGP Community attribute to them. I am using an inbound route-map on the BGP peer for this purpose, however it does seem to work.   Is this the correct way to do this ?   config router route-map edit "HG_CORP_ROUTE_MAP_IN" config rule edit 10 set match-origin egp***matching all learned incoming BGP routes set set-community "7714:65100"***setting the community
Hello, I am trying to convert incoming port 22 to 2222 with a VIP rule. However I want to keep the same external and internal IP address. The VIP will not accept this. Is there any way to only conve... See more...
Hello, I am trying to convert incoming port 22 to 2222 with a VIP rule. However I want to keep the same external and internal IP address. The VIP will not accept this. Is there any way to only convert incoming ports with the same address ?
Hello, I have a single public IP address on my Fortigate. If I configured an IPSec tunnel using this address, will this interfere with my regular Internet bound traffic and incoming VIPs that also s... See more...
Hello, I have a single public IP address on my Fortigate. If I configured an IPSec tunnel using this address, will this interfere with my regular Internet bound traffic and incoming VIPs that also share this same public IP address ? Or should I ask the ISP for an additional public IP address for my IPSEC tunnel ? Thank you.